F-Droid at 36c3
f-droid.org
f-droid.org
Same with screen shots, it can take 15+ seconds for screenshot thumbnails or full screen shots to load. It is like being on dial up.
I know it is open source and I should not complain.
Personally I just look for apps elsewhere and install them through F-Droid when available (like Telegram, Firefox (fennec), piggybudget, OsmAnd, reddit reader, Öffi, K-9 mail, Newpipe, ssh connectbot, wifi analyzer, simple file manager & gallery, QR code scanner, muPDF viewer, etc. I all have through f-droid instead of the google ecosystem). The only exception is the "new" section that opens by default when you launch the F-Droid app: there I browse when there is new stuff.
Aurora Store fetches packages from the same source as the Google Play client. There's a legitimate benefit to having access to the Google Play catalog without depending on Google Play Services or owning a Google account, and not all apps on Google Play are malware.
Definitely agree, use store personally, have done all that is possible to degoogle my phone but the reality is that certain play store apps are essential for modern living. Yalp was once good but find it unusable now. Aurora store has good UI and seems to handle the proxy accounts better, or at least they are not being banned so quick.
Looking at their bug reports the issue may have been fixed, and anecdotally I haven't had any issues recently.
[0]: https://f-droid.org/en/packages/org.gdroid.gdroid/ [1]: https://gitlab.com/fdroid/fdroidclient/issues?scope=all&utf8...
versions after 0.102.3 were just terrible and i reverted immediately. Of course a lot of folks don't seem to mind the modern view but I find itv extremely unusable.
Supposedly a clone called GDroid shows ratings and such as well.
All in all, it's far cry from what a "best in class" app store could be.
They don't use one AFAIK. They have mirrors, but the way stuff works is that their main server is still the bottleneck. This has been raised before (https://forum.f-droid.org/t/why-is-fdroid-down-all-the-time/... and a few other threads on the forum) without a satisfactory resolution. As an outsider, to me it appears that f-droid's user base is mostly European, and it works well enough for people in Europe.
Nah, you should complain. Open source is not an excuse for broken functionality.
To help find apps here is a 3-line script to produce a tab-separated list of apks with one line descriptions
curl -4o name https://gitlab.com/fdroid/fdroiddata/raw/master/stats/known_apks.txt
curl https://gitlab.com/fdroid/fdroiddata/-/archive/master/fdroiddata-master.tar.bz2?path=metadata| bzip2 -dc|tar xOf - --wildcards *en-US/summary.txt|sed '/^In the list of classes/d' > desc
paste name desc|cut -d / -f3,5|less
This one-line script outputs a 1.4M list of longer descriptions found in the YAML files curl https://gitlab.com/fdroid/fdroiddata/-/archive/master/fdroiddata-master.tar.bz2?path=metadata| bzip2 -dc|tar xOf - --wildcards *.yml|sed -n '/AutoName:/p;/./{/Description:/,/versionCode:/{/^ /p;#thats 3 spaces;};}'|less
This outputs list of latest apks curl https://gitlab.com/fdroid/fdroiddata/blob/master/stats/latestapps.txt
Because the website has always been so slow, almost unsuable for search or browsing, I download text and make lists of the F-Droid apks with descriptions and other metadata. Then I can browse and search through these text files to find apps using less(1), grep(1), etc., instead of using the website or F-Droid app.Then when I know what I want I download the source or .apk file from the website. It's a slow website but it's a good project otherwise. Appears they are funded by same organization that wrote libldns, nsd, unbound, drill, etc.
That said, yes, the official client could be improved, and we welcome contributions. The security side of F-Droid is quite solid, that's the problem with the various forks. They focus on UX, without the careful attention needed for security. The ideal world would be that the core of the official F-Droid client would be a standalone library, so that the forks can have the same solid base. We welcome contributions there.
https://repeatr.io/welcome/what-is-timeless/ explains timeless as a set of tooling for reproducible builds with a broader and more hash-based mandate than what's out there currently. While early, it seems like it's a reasonable path towards getting a reproducible system that won't fall apart as fast over time, by vendoring the dependency system in the same way modern language-specific package managers do, but at a language-agnostic/distribution level.
FWIW, I'm using Nix to package Android app builds in a reproducible way (for React Native apps).
I speculate that the container approach will make porting slightly easier as dependancies can be placed where they are expected, thus no patches are required for project build systems. On the other hand producing a self contained executable seems more difficult, and I wonder if they'll go with an AppImage like approach to minimise patches required.
Overall the vision has overlap but the end result is very different from that of NixOS and Guix.
[0]:
> Typically, we use an executor which uses “linux containers”. However, for the most part, we try to consider that an implementation detail. Executors might also be simple chroots; or virtual machines; or other interesting kinds of sandboxing. Nor are executors strictly limited to the Linux operating system; it's simply the most common place to work. https://repeatr.io/design/executors/
[1]:
> Radix “Packages” are similar to packages from other linux distributions… however, we're aiming to do something not like linux distributions: our vision for Radix Packages is that they go anywhere, with or without the rest of a distro associated with them. https://repeatr.io/welcome/what-is-radix/
Now maybe that makes sense for what for what f-droid is but often I couldn't tell what some apps even did... if they would work on my phone (a surprising number did not)...
Stickers, really? Is it major thing needed to include in 36c3 report?
https://twitter.com/spacerog/status/1197613616171749376 & https://twitter.com/spacerog/status/1204056842999156736
But... I mean, that, as its significant sub-subculture, it should be placed as last line in this article; not at the core list.
Maybe I'm not sub-subhacker. Yet.